Feeds

eBay pulls Vista laptop pwned in hacking contest

Do no harm

Reducing security risks from open source software

An eBay listing for the Windows Vista laptop that was successfully compromised at last week's Pwn2Own hacking contest was removed after the online auctioneer said it violated terms that forbid sales of items that might do harm.

Shane Macaulay, who felled the machine with code that attacked a weakness in Adobe Flash, posted the listing late Monday night, California time. Within two hours, he said in an interview, he received an automated email that said the auction had been suspended.

According to this article by IDG News, the listing read: "This laptop is a good case study for any forensics group/company/individual that wants to prove how cool they are, and a live example, not canned of what a typical incident response sitchiation [sic] would look like."

"At least on the eBay item, I was being a little sensationalistic, but I was just trying to get a sale," he told El Reg. He said he didn't mean to break contest rules that forbid the disclosure of the flaw or exploit code prior to there being a patch.

"By the time they would have gotten it (the laptop), I'm positively sure it would be patched," he said. "The reason i didn't say that outright (was) i wanted to ... see what the market would pay for" the unpatched vulnerability.

Macaulay was one of two attendees to take a prize during last week's contest at the CanSecWest conference in Vancouver. Charlie Miller and two two other researchers from Independent Security Evaluators, won $10,000 for a previously unknown Safari browser exploit that brought down a fully patched MacBook Pro. Macaulay, who was aided by researcher Alex Sotirov, won $5,000 for their exploit. Winners were also permitted to keep the machines. A third laptop running Ubuntu remained standing.

The cash prize is paid by 3Com's Tipping Point division, whose Zero Day Initiative pays bounties to researchers who responsibly disclose vulnerabilities. One condition imposed on sellers is that they provide no details of the vulnerability.

A spokeswoman for eBay told IDG the wording of Macaulay's listing led them to think the laptop could do someone harm. ®

Mobile application security vulnerability report

More from The Register

next story
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Microsoft: You NEED bad passwords and should re-use them a lot
Dirty QWERTY a perfect P@ssword1 for garbage websites
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
NUDE SNAPS AGENCY: NSA bods love 'showing off your saucy selfies'
Swapping other people's sexts is a fringe benefit, says Snowden
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
British data cops: We need greater powers and more money
You want data butt kicking, we need bigger boots - ICO
Crooks fling banking Trojan at Japanese smut site fans
Wait - they're doing online banking with an unpatched Windows PC?
NIST told to grow a pair and kick NSA to the curb
Lrn2crypto, oversight panel tells US govt's algorithm bods
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Mobile application security vulnerability report
The alarming realities regarding the sheer number of applications vulnerable to attack, and the most common and easily addressable vulnerability errors.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.